# GovExpress vulnerability disclosure — RFC 9116 # Human-readable policy: https://govexpress.ai/security/vulnerability-disclosure/ # There is no bug bounty. We do not pay for reports; the policy says so up front. # URLs carry the trailing slash deliberately — the no-slash form 302s. Contact: mailto:security@govexpress.ai Expires: 2027-09-06T00:00:00.000Z Policy: https://govexpress.ai/security/vulnerability-disclosure/ Preferred-Languages: en Canonical: https://govexpress.ai/.well-known/security.txt